Legal

Privacy Policy

This page explains how the product handles account data, billing, support, connected devices, and emergency sharing.

Effective Date: May 6, 2026 Last Updated: May 6, 2026

This Privacy Policy explains how Hardware Hub Consulting, LLC ("Talo 360," "we," "us," or "our") collects, uses, shares, retains, and protects information when you use https://talo360.app, our apps, native mobile experiences, and related services (together, the "Service").

Talo 360 is a consumer health app. The Service helps users create accounts, manage health profiles, connect health and provider integrations, sync records, manage subscriptions, submit feedback, use device and voice features, and optionally create public emergency / ICE sharing links.

Information We Collect

We collect information you provide directly to us, information you direct third parties to send to us, information generated through your use of the Service, and information collected automatically to operate and secure the Service.

  • Account and sign-in information. This includes your email address, account credentials, sign-in method, and account identifiers associated with Apple sign-in, Google sign-in, or email/password access.
  • Profile, onboarding, and health information. This includes information such as display name, sex, height, weight, blood type, allergies, conditions, medications, emergency details, and other health or wellness information you choose to add to the Service.
  • Connected health and provider import data. If you connect supported services, we may receive health and records data from Apple Health / HealthKit, Android Health Connect, Dexcom, and patient-authorized EHR or SMART on FHIR integrations, along with connection status, sync history, source metadata, and authorization details needed to maintain those connections.
  • Voice and device feature data. If you use voice or native device features, we may collect command text, related event or sync metadata, device identifiers, platform details, app version information, and timestamps associated with those features.
  • Billing and subscription data. If you purchase a subscription or other paid feature, we receive billing and transaction metadata such as plan type, subscription status, checkout and invoice records, and Stripe customer or transaction identifiers. Payment card details are processed by Stripe and are subject to Stripe's own privacy practices.
  • Support and feedback submissions. If you contact us or send feedback, we collect the contents of your message and any app context you choose or allow us to include, such as device type, app version, connected providers, screen context, and issue details.
  • Technical, session, and security data. We collect information such as IP address, browser or device type, operating system, app version, cookies or similar session technologies, authentication events, error logs, crash or diagnostic data, and security signals used to protect the Service.

How We Collect Information

We collect information in several ways: directly from you when you create an account, complete onboarding, enter health information, submit feedback, or use app features; from connected integrations when you choose to connect Apple Health / HealthKit, Health Connect, Dexcom, or other supported health sources; from healthcare providers or healthcare systems when you authorize an EHR import or SMART on FHIR connection; from your devices and native integrations when you use supported device or voice features; and automatically through the normal operation, security, and administration of the Service.

How We Use Information

We use information to provide and improve the Service, including to create and manage accounts, authenticate users, maintain sessions, display and organize health information, generate health summaries and records views, operate connected-device and EHR sync features, process billing and subscriptions, respond to support and feedback, review and improve product quality, maintain logs and audit trails, protect against fraud and unauthorized access, enforce our terms and policies, and comply with legal obligations.

Authenticated Health Surfaces and Advertising

Talo 360 is designed to be privacy-forward. We do not use ad-tech trackers on authenticated surfaces of the Service that display or process health information. We may use operational technologies that are reasonably necessary to run, secure, debug, and improve the Service, such as session cookies, security logging, and service-performance monitoring.

How We Share Information

We do not sell your personal information as part of an advertising business model. We may share information in the following circumstances:

  • Service providers and infrastructure vendors. We may share information with vendors that help us host, store, secure, authenticate, support, maintain, and operate the Service.
  • Payment processing. We share billing-related information with Stripe and related payment partners to process subscriptions, purchases, refunds, and billing support requests.
  • Connected health and provider integrations. When you request a connection, sync, or import, we may exchange information with the integration, provider system, or interoperability partner needed to complete that request.
  • With your direction. We share information when you ask us to, including when you create and share an emergency / ICE link or request a records import, export, or connection.
  • Legal and safety reasons. We may disclose information if required by law, subpoena, court order, regulatory request, or when we believe disclosure is reasonably necessary to protect users, the public, our rights, or the Service.
  • Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be disclosed as part of that transaction, subject to applicable confidentiality and legal requirements.

We may also use or disclose de-identified or aggregated information that does not reasonably identify you.

Emergency / ICE Sharing Links

Talo 360 may allow authenticated users to create public emergency or ICE sharing links. These links are optional and user-controlled. If you create and share one, anyone with the link may be able to access the emergency information made available through that link until the link is revoked or expires. These links are intended to expose limited emergency-facing information, not your full authenticated account. You are responsible for deciding whether to create, share, or revoke these links and for sharing them carefully.

Data Retention and Deletion

We retain information for as long as reasonably necessary to provide the Service, maintain your account, complete requested syncs or transactions, preserve security and fraud-prevention records, resolve disputes, enforce agreements, comply with legal obligations, and maintain backup and disaster-recovery systems. Retention periods may vary by data type and use case.

If you request deletion or close your account, we will delete or de-identify information within a reasonable period unless we need to retain it for legal, operational, security, fraud-prevention, backup, or other legitimate business purposes. Disconnecting an integration will stop future collection from that source, but previously imported data may remain unless you delete it or request deletion. Backup copies may persist for a limited period until they are overwritten in the ordinary course.

Security

We use administrative, technical, and organizational safeguards designed to protect information appropriate to the nature of the data and the Service. These measures may include access controls, authentication safeguards, encryption in transit and at rest where appropriate, logging, monitoring, and vendor controls. No system is completely secure, and we cannot guarantee absolute security.

If you believe your account or information may have been compromised, contact security@talo360.app.

Your Choices and Rights

You can choose whether to provide certain profile and health information, whether to connect supported integrations, and whether to create public ICE links. You may access and update certain information in the Service, disconnect integrations, revoke ICE links, and manage certain communication preferences. You may also contact us to request access, correction, or deletion of your information. We will review and respond to requests in accordance with applicable law and our operational and security obligations.

HIPAA-Related Clarification

Talo 360 may receive, store, and process health-related information, including information you enter yourself and information you direct us to import from connected devices or healthcare providers. However, this Privacy Policy is not a statement that Talo 360 is a HIPAA covered entity, that all information in the Service is protected by HIPAA, or that the Service is HIPAA compliant in every context. In many cases, consumer health apps are governed by privacy commitments like those in this Policy and by other applicable laws. Healthcare providers and integration partners may also apply their own privacy notices and legal obligations to information they handle.

Children's Privacy

The Service is not intended for children to use independently on their own behalf. A parent, guardian, or caregiver may use the Service to manage information for a child or dependent where permitted. If you believe a child has provided information to us in a way that is not permitted, please contact us so we can review and take appropriate action.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make changes, we will post the updated version here and update the "Last Updated" date above. If a change is material, we may also provide additional notice through the Service or by other appropriate means.

Contact Us

If you have questions, requests, or concerns about this Privacy Policy or our privacy practices, contact us at:

Hardware Hub Consulting, LLC Privacy Email: privacy@talo360.app Support Email: support@talo360.app Security Email: security@talo360.app Mailing Address: 2256 Northlake Parkway, Ste 110 PMB 1033, Tucker, GA 30084